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REMARKS 



Claims 1-30 are pending and are unamended. Withdrawal of aJl objections and rejections 
are respectfully requested for at least the reasons set forth below. 

Grounds of Rejections 



Numerous errors appear to have been made in the grounds of rejection. A telephone call 
was made to the Examiner on July 8, 2003 to attempt to clarify the grounds of rejection, bui the 
Examiner refused to review the application for clarification of any of the grounds. Applicants 
have presumed that the rejections should have read as follows: 

L The 35 USC § 112, first paragraph, rejection was presumed to also include claim 1 
since the limitation raised by the Examiner appears in claim 1 . 

2. The 35 USC § 103 rejection of claims 2 and 17 was presumed to be in view of 
Montulli, Wagner and Dutta, taken in combination. 

3. The 35 USC § 103 rejection of claims 15 and 30 was presumed to be in view of 
Touboul, Montulli and Wagner, taken in combination. 

Prior Art Rejections 

1. Claims 1 and 16 are Patentable over Montulli C242) 

Claim 1 is directed to a method of screening cookies in a client machine* A server 
receives a request from a subscriber to send a list of cookie file sources to the client machine . 
The list is downloaded from the server to the client machine. The downloaded list is then used to 
detect cookie files received at the client machine from sources on the downloaded list. 

In one embodiment of the claim 1 invention, the list may include web sites (cookie file 
sources) which are known to send cookies that when stored on a user's computer compromise a 
computer user's privacy. For example, some web sites send out cookies that track a user's web 
site navigation and report the results back to a designated web site, all without knowledge to the 
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user. See, for example, the discussion of how Doubleclick cookies are used on page 13 of 
Appendix A\ 

It is virtually impossible for an individual computer user to keep track of all of the web 
sites that send out undesirable cookies. The method in claim 1 allows a monitoring entity (o,g_, 
a service provider) to keep track of such web sites and send a list of such web sites to a client 
machine upon request During subsequent navigation by a user at the client machine, the li^t can 
be used to detect cookie files when a web site on the list is encountered by the client machine. 
Upon detection, the cookies files can be removed from the client machine and/or prevented From 
being stored, as recited in dependent claims 5 and 6. (Independent claim 1 is more broadly 
directed to using the list to detect cookie files.) 

Montulli 0242), hereafter, "Montulli, is a well-known patent that is touted as describing 
the original concept of a cookie. See page 1 1 of Appendix A, especially footnote 20. (U.S. 
Patent No. 5,774,670 is the parent patent of Montulli '242.) The portions of Montulli referenced 
by the Examiner in the outstanding Office Action merely describe the purpose of a cookie, how 
cookies are sent, and what they do on a client machine. Montulli thus describes sending and 
using cookie flies. Nowhere does Montulli describe creating lists of cookie file sources (claim 1 
step (a)), downloading cookie file lists (claim 1, step (b)), or using a downloaded list to detect 
cookie files (claim 1, step (c)). Claim 1 is directed to a specific process to assist a user in 
screening cookies files, not to the very concept of a cookie itself as described in Montulli. 

To anticipate a method claim, a reference must disclose each and every step in the cl;iim. 
Here, Montulli fails to disclose any of the steps in claim 1. In sum, Montulli has nothing 
whatsoever to do with the claimed invention and thus the rejection of claim 1 over Montulli 
should be withdrawn. 

Claim 16 is similar to claim 1 and is thus patentable over Montulli for the same reasons 
as discussed above with respect to claim 1. 



1 Shah, R.C. et aL "Governance Characteristics of "Code": The Rote of Transparency, Defaults and 
Standards," 2002 Telecommunications Policy Research Conference, September 28-30, 2002, Alexandria Virginia, 
article posted on web site: http://inteLsi.uirdch.ed^ 

printout date: October 23, 2003, 30 pages (Appendix A includes pages 1 and 10-14 only). 
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2. Patentability of Claims 7 and 22 over Dutta 

Claim 7 is directed to a method of creating a composite list of cookie file souices in a 
client machine. A first exception list is created that includes the identity of sources that are 
permitted to store cookie files in the client machine. A second exception list is created that 
includes the identity of sources that are not permitted to store cookie files in the client macliine. 
A client machine receives a master list of cookie file sources from a service provider. The master 
list is then modified in accordance with the first and second exception lists. The composite list is 
the modified master list. 

Claim 7 is also related to the list of claim 1, except that it allows a user to modify th*> list 
(referred to as a "master list"). In one embodiment of claim 7, a user can customize a defau It, 
master list with trusted and untrusted web sites identified by the user. 

Dutta discloses an "unmodifiable cookie." One purpose of the unmodifiable cookie is to 
address a problem in the art described in paragraph [0007] as follows: 

[0007] Web merchants commonly use cookies to track subscriptions they 
provide for Web content such as newsletters, magazines, etc. To entice 
potential permanent subscribers, the Web merchant often provides a free 
trial subscription to a user. The trial subscription is tracked using a cookie 
and once the free period expires, the merchant notifies the user in hopes 
that the user will purchase a subscription. This marketing model is not 
without its problems for example, the user has the ability to change his 
identity and register a subsequent time for the same free subscription. 
This can be done by removing and/or modifying the cookie resident on his 
computer. The merchant then loses a potential subscriber. Therefore an 
unmodifiable cookie that resides on the client machine wouid help to 
alleviate this problem. 

As described in paragraphs [0032] and [0033], encryption and hash functions may be used to 

make an unmodifiable cookie and to ensure that the cookie has not been altered when it is 

received at a host site. Dutta also discloses a process for allowing a browser to be set to eith^T 

accept or reject "unmodifiable cookies" in the same manner that a conventional browser can be 

set to accept or reject normal (modifiable) cookies. See paragraph [0034]. For example, Internet 

Explorer has various security and privacy settings that determine how incoming cookies are 

handled. Dutta contemplates adding additional settings to address the handling of unmodifiable 

cookies. 
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Nowhere does Dutta disclose or suggest tracking cookie file sources (e.g., web sites ) that 
are or are not permitted to store unmodifiable cookies in a client machine (claim 7, steps (a > 
and (b)). At best, Dutta discloses examining an incoming cookie and storing ox not storing the 
cookie or treating the cookie in a special manner on a client machine depending upon whether or 
not it is an unmodifiable cookie (steps 314-320 of Fig. 3 and paragraph [0034) of Dutta). Nor 
does Dutta disclose or suggest a client machine that receives a master list of cookie file sou rces 
from any location (claim 7, step (c)) t or the ability to modify the master list based on exception 
lists (claim 7, step (d)). 

To anticipate a method claim, a reference must disclose each and every step in the claim. 
Here, Dutta fails to disclose any of the steps in claim 7. In sum, Dutta has nothing whatsoever to 
do with the claimed invention and thus the rejection of claim 7 over Dutta should be withdrawn. 

Claim 22 is similar to claim 7 and is thus patentable over Dutta for the same reasons as 
discussed above with respect to claim 7. 

3. Patentability of Claims 12 and 27 over Touboul 

Claim 12 is directed to a method of creating a composite list of cookie file sources in a 
client machine. A client machine receives a master list of cookie file sources from a service 
provider. Cookie file sources that correspond to one or more trusted cookie file sources listed in 
the client machine are deleted from the master list likewise, cookie file sources that correspond 
to one or more untrusted cookie file sources listed in the client machine are added to the master 
list The composite list is the master list as modified by any additions and deletions of trusted 
and untrusted cookie file sources. 

Touboul discloses a process for treating "Downloadable^" A "downloadable" refer* to a 
"downloadable application program." (column 1, lines 43-44). A downloadable is further 
described in column 1, lines 44-57 which reads as follows: 

A Downloadable is an executable application program , which is 
downloaded from a source computer and run on the destination computer. 
Downloadable is typically requested by an ongoing process such as by an 
Internet browser or web engine. Examples of Downloadables include 
Java™ applets designed for use in the Java™ distributing environment 
developed by Sun Microsystems, Inc., JavaScript scripts also developed 
by Sun Microsystems, Inc., ActiveX™ controls designed for use in the 
ActiveX™ distributing nvironment developed by the Microsoft 
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Corporation, and Visual Basic also developed by th Microsoft 
Corporation, Therefore, a system and method are needed to protect a 
network from hostile Downloadable, (underlining added for emphasis) 

Security policies can be set regarding downloadables. For example, the URL from 
which the Downloadable originated from can be compared against trusted and untrusted URLs, 
and the result of the comparison may be used to allow or block the Downloadable (column 2, 
lines 17-20; column 6, lines 38^8). 

Touboul has nothing whatsoever to do with cookie files or cookie file sources , 
Downloadables are executable application programs that are run on a client machine, when- as 
cookie files are merely data files which are not executed or ran. Thus, Touboul does not di>close 
or suggest claim 12, steps (a)-(c). Even if it presumed that the manner in which Touboul handles 
downloadables can be applied to cookie files (a presumption that Applicants disagree with). 
Touboul still does not disclose or suggest the process in claim 12. 

Touboul describes nothing more than a locally generated static security policy for 
downloadables, not a process for distributing a security policy for downloadables from a service 
provider to a client machine which can then be customized at the client machine. There is n o 
concept of a "service provider" in Touboul that maintains a master list of downloadables. 1 he 
Examiner states that column 2, line 17 of Touboul discloses "receiving a cookie master list j rom 
[a] server." As discussed above, column 2, line 17 merely describes that a URL from which a 
Downloadable originated from can be compared against trusted and untrusted URLs, and flus 
result of the comparison may be used to allow or block the Downloadable- Nowhere does this 
sentence disclose or suggest that a service provider maintain the list of trusted and untrusted 
URLs, or that the list is sent from a service provider to a client machine, as recited in claim 1 2, 
step (a). 

In contrast to Touboul, claim 12 provides a method wherein a master list of cookie fi Je 
sources are sent from a, service provider to a client machine. The client machine can then add or 
delete cookie file sources to and from the master list to create a composite list. In this mannor, 
each client machine can develop its own personalized list, starting with the original master li st. 

Hie Examiner further concedes that Touboul lacks any disclosure of deleting or addi i ig 
cookie file sources, as recited in claim 12, steps (b) and (c), but then asserts that these steps 
would have been obvious to an artisan "for the purpose of providing tests to determine whether 
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to allow or block a downloadable" as described in column 2, line 20 of Touboul. This rea& ming 
is incorrect. The tests referred to in column 2, line 20 is merely a test of a URL that a user has 
navigated to (or wants to navigate to) against a preestablished list of trusted and untmsted \ fRLs. 
No deleting from or adding to that list is required to perform the test described in Touboul, nor 
does Touboul suggest that the list may be or should be customized by a user. Li sum, the 
Examiner is improperly modifying Touboul by using improper hindsight reconstruction of 
Applicants 9 invention. 

To render a method claim as being obvious, a reference must disclose or suggest eac h and 
every step in the claim. Here, Touboul fails to disclose or suggest any of the steps in claim 12. 
In sum, Touboul has nothing whatsoever to do with the claimed invention and thus the rejec don 
of claim 12 over Touboul should be withdrawn. 

Claim 27 is similar to claim 12 and is thus patentable over Touboul for the same reasons 
as discussed above with respect to claim 12. 

4. Patentability of Dependent Claims 2-6. 8-11, 13-15. 17-21. 23-26 and 28-30 

The dependent claims are believed to be allowable because they depend upon respective 
allowable independent claims, and because they recite additional patentable steps. Wagner Joes 
not make up for any of the highlighted deficiencies in the references applied against the 
independent claims. 

35 VS.C § 112, First Paragraph, Rejection 

The Examiner alleges that the specification fails to provide an enabling disclosure of how 
to obtain a list of cookie files from a server. Applicants traverse this rejection. 

Page 6, lines 1-4 of the specification describes one process for obtaining a list of cootie 
files from a server, and reads as follows: 

As shown in FIG. 1 , the present invention begins with the use of a privacy 
server 10, which maintains a watch list 12 of privacy protection criteria 
(e.g., a list of untrusted cookie file sources) and sends over a network a 
local copy of the watch list 14 to client machine 20 In response to a 
request received from a subscribing user of client machine 20. 
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The process for causing a client machine to make a request for a data file over a network (e.g., 
the Internet, as clearly implied by the use of URLs in the specification) is extremely well-known 
in the art This process is no different than accessing any type of file that is on a remote server. 
An application merely opens an Internet connection and makes a request 

A search on google.com of: "how to download" "data file" server 
returned 753 results, many of which describe exactly how to download data files using 
conventional computer software and hardware components (Appendix B). Another search * m 
google.com of: "download a data file" 

returned 2,360 results, many of which also describe exactly how to download data files using 
conventional computer software and hardware components (Appendix B). 

Since the list of cookie files is just a data file, any conventional process for downloaifing 
a data file from a server can be used for this process. In sum, it is believed that an artisan would 
have known how to obtain a list of cookie files from a server using the above-highlighted 
description of the process in the specification, in conjunction with well-known file downloading 
processes. 



Claim 7 was rejected for allegedly lacking an antecedent basis for "the composite lisi." 
This rejection is traversed, line 1 of claim 7 recites "a composite list" and thus provides a 
sufficient antecedent basis for "the composite list" which appears in line 10 of claim 7. 
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Conclusion 



Insofar as the Examiner's rejections were fully addressed, the instant application is in 
condition for allowance. Issuance of a Notice of Allowability of all pending claims is there! ore 
. earnestly solicited. 



Respectfully submitted, 



ADAM R. SCHRAN et al. 
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Governance Characteristics of "Code": The Role of Transparency, Defaults, 

and Standards 



Rajiv C. Shah* & Jay P. Kesan** 



2002 Telecommunications Policy Research Conference 
September 28-30, 2002 
Alexandria, Virginia 



Abstract; 

Regulation through "code," i.e., the hardware and software of communication 
technologies, is growing in importance. Policymakers are addressing societal concerns such ,is 
privacy, freedom of speech, and intellectual property protection with code-based solutions. 
While scholars have noted the role of code, there is little analysis of the various features or 
characteristics of code that have significance in regulating behavior. This paper examines tb 
social, technical, and legal ramifications of three universal governance characteristics of code 
that are significant in regulating behavior. The characteristics are crucial in understanding how 
code operates as well as the various possible regulatory settings for code. These characteristics 
studied are transparency, defaults, and standards. 

These characteristics were identified through a number of case studies, which explored 
how code regulates by studying code in a variety of historical periods, developed within different 
types of institutions, and based upon diverse expectancies of user competencies. The case 
studies include the Finger protocol, Netscape's cookies technology, and the Platform for Inta net 
Content Selection developed by the World Wide Web Consortium. 

The first characteristic analyzed is transparency. Transparency in code allows people to 
understand how code operates. This allows people to make an informed decision when using 
code. For regulators, transparency allows them to ensure code properly addresses issues of 
societal concern. For example, a key complaint of content filtering software is its lack of 
transparency. Users and policymakers do not know what material is and is not being blocked. 
We discuss several important regulatory issues with transparency, including its contextual nalure 
and dependence upon implementation. 

The second characteristic is the role of defaults. Defaults set the condition for how cotle 
operates in the absence of intervention. Defaults are a method regulators can use to ensure 
people have multiple options when using code. We discuss the importance of defaults, their 
power, and also why people may not follow default settings. An example of the use of defeulis 
concerns privacy. Should the defaults of code be designed so people have to intervene to prelect 
their privacy or only intervene when giving up personal information? 

The third characteristic is standards. We use this term broadly to encompass open 
standards that allow for interoperability as well as modularity that saves developers from 
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In the 5 years that I have been at CMU, I have watched a decline of direct person- 
to-person talking and an increase of computer-based conferencing of all kinds. I 
have seen people send computer mail to someone ten feet away to avoid having to 
get out of a chair and actually use his vocal cords. I have seen an increasing 
number of design discussions take place entirely within the confines of the 
computer. And I have watched the "sense of community" that is so valuable to 
research institutions become weaker and weaker" [. . J Personal privacy in the 
face of computer systems and data bases is a very sticky problem, but it is not the 
problem that I was trying to address with my complaints about closedness. I was 
worried, and still am worried for that matter, about the decay of our lab as a place 
in which to do research and creative thinking. I certainly dont want some credit 
bureau to know when I last logged out of the machine, but I certainly do want my 
co-workers to know when I did The question of "who is asking" is to me very 
important. 



This discussion over privacy rights in 1979 resembles many contemporary concerns oven- 
privacy. In our future work, we will carefully analyze this controversy. However, for this pa per 
we choose to focus on how changes in code affected privacy. 



S. Cookies 

Cookies are part of several technologies Netscape developed in order to position its M eb 
servers for commerce. The cookies technology was the most innovative feature and one that 
would forever alter the web. According to Lessig, "before cookies, the Web was essentially 
private. After cookies, the Web becomes a space capable of extraordinary monitoring.*' 9 In 
early web browsers, the Internet was a stateless place. A stateless web is analogous to a vend ing 
machine. It has little regard for who you were, what product you are asking for, or how manv 
purchases you have made. It has no memory. The lack of statelessness on the web makes 
commerce difficult. For example, without a state mechanism, buying goods is analogous to 
using a vending machine. You could not buy more than one product at a time and there wouM 
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be no automatic one-click automated shopping feature that remembers your personal 
information. 

Cookies solve the statelessness problem by storing data on the users computer. Lou 
Montulli and John Giannandrea developed the cookies technology or more formally tided, 
Persistent Client State HTTP Cookies. 20 Programmers used the term cookies to refer to a small 
data object passed between cooperating programs. Similarly, Netscape would use cookies to 
pass information between a user's computer and the web site they were visiting. The first use of 
cookies was by Netscape to determine if visitors to Netscape's web site were repeat visitors < »r 
first time users. 21 

Cookies were incorporated in the earliest version of Netscape's web browser released in 
1994. Cookies were not made public to users in several ways. Netscape turned the feature on by 
default without notifying or asking the consent of users. 22 Second, there was no notification 
mechanism to alert people when cookies were being placed on their computer. Users did not 
know that information about them was being saved. Third, the cookies technology was not 
transparent. Examining a cookies file provides no information about what is stored in the cookie 
file. Fourth, there was no documentation available that explained what cookies were and their 
privacy implications; 23 



19 John Schwartz, Giving the Web a Memory Cost Its Users Privacy, N.Y. TIMES, Sep. 04, 2001, available at 
http-7/www.nylimes-com/200 l/09/04Aechnology/04Cook.html. 
M /</. See also Netscape, Persistent Client State HTTP Cookies, at 

http://home^tscapQXQm/n^ (last visited Sep. 19, 2001) (the original Netscape 

specification on cookies); Persistent Client State in a Hypertext Protocol Based Client-Server System, U.S. Paten* 
No. 5,774,670 (issued June 30, 1998) (filed on Oct 6, 1995), SIMON St, LAURENT, COOKIES (1998) (providing Em 
excellent overview of cookies and how to use thorn). 

2J Netscape browsers default home page is Netscape's web site. This meant every user would visit Netscape's wrb 
site at least once. See Alex S. Vieux, The Once and Future Kings, RED HERRING, Nov. 1, 1995. 
22 LynetCeLMttlettetaL, Cookies and Web Browser Design: Toward Realizing Informed Consent Online, CHI 2001 
Proceedings, at 46 (2000) (conducting an analysis of cookie management tools in web browsers). 

In fact, technically proficient users in 1 995 called for Netscape to document the cookies feature. For example, 
Marc Hedmnd listed me following problems with Netscape's implementation of cookies, "1 . Why doesn't the woitl 
"cookie" appear in the Netscape Online Handbook?, 2. Why isn't the cookie specification URL given in any 
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Netscape incorporated cookies into its web browsers released in 1 994. It was not until 
early 1996 that the public became aware of cookies. The Financial Times broke the story on 
February 12, 1996 with an article on cookies and privacy. 24 The article immediately drew 
attention to cookies and resulted in a great deal of uproar about the use of cookies. Over the next 
few years, cookies became one of the top Internet privacy issues. 

Netscape's cookies led to Internet Engineering Task Force (IETF) to begin work on a 
standard for state management on the Internet. The IETF, as the de facto Internet standards 
body, sought to ensure there was a complete technical specification on state management 
Eventually, they decided to use the Netscape's cookies specification as the basis for the lETf "s 
standard. However, the standards process soon ran into problems. 25 The DSTF found that 
Netscape's implementation of cookies was fraught with privacy and security problems. 

The most serious problem was third party cookies. The intent of Netscape's cookies 
specification was to only allow cookies to be written and read by the web site the person was 
visiting. For example, if the New York Times placed a cookie on a computer, Amazon.com 
could not read or modify the New York Times cookie. This provided security and privacy b} 
only allowing sites access to im^ormation they authored. However, Netscape's cookies 
specification allowed third party components of a v/eb page to place their own cookies. This 
created a loophole by which third parties could read and write cookies. This security and prh acy 
defect was the outgrowth of the rapid development and incorporation of the cookies technology. 



README or impkanenfetion notes file?, ... [3] How are users supposed to know what information is being kept 
about them, or for how long?" Marc Hedhind, State Wars, part XI (was: Revised Charter), HTTP-WG MAILING 
LIST, Nov. 1, 199S, available at http://wwics.iK:te^ 

Tim Jackson, This Bug in Your PC is a Smart Coafde, FIN. Times, Feb. 12, 1996. The next day a similar starj 
appealed m tbe United States. See Lee Gomes, Web 'Cookies" May Be Spying on You, SAN JOSE MERCURY New* 
Feb, 13, 1996. 

25 David M. Kristol, HTTP Cookies; Standards, Privacy, and Politics, ACM TRANSACTIONS Internet TECH >f ov 
2001, at 10. "* 
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This loophole has led to a uew breed of businesses, the online advertising management 
companies. 26 

Third party cookies can be used by online advertising companies to create detailed 
records on a person's web browsing habits. Many sites contract out their banner advertising to 
advertising management companies. These companies find advertisers for web sites and ensure 
that their banners appear on the web site. For example, DoubleClick sells advertising space <m 
sites such as ESPN and the New York Times. Doubleclick is also responsible for placing the 
banner advertising on their client's web site. Through the loophole of third party cookies, 
Doubleclick uses its advertising banners on an ESPN web page to place a cookie when a pel son 
visits ESPN. Doubleclick can then read and write to that same cookie when the same person 
visits the New York Times web site. 27 This allows Doubleclick to aggregate the information 
about a person's web surfing from its client web sites. They can then create a detailed profile of 
a person's surfing habits. This has obvious and serious privacy implications. 28 

The lETF's cookies standard is critical of third party cookies allowed by Netscape's 
cookies specification. The standard states that third party cookies must not be allowed It does 
allow an exception if the program wants to give the user different options. However, the 
baseline default must be set to off. 29 It also requires that the user be able to disable cookies, 
determine when a statefiil session is in progress, and be able to save cookies depending upon the 
cookies domain. This last one is especially significant, because it allows users to manage what 
sites can and can't place cookies. 

M Schwartz, supra note 19. 

27 Kristol, supra note 25 at 30, 

28 Michael Go wan, How It Works: Cookies, PC WORLD, Feb. 22, 2000, available at 
httpr//Ww.pcworld.win^ 

* 9 David Ktistol & Lou Montulli, HTTP State Management Mechanism, RFC 2965, Oct 2000, available at 
ftp^/ftp.isLodu/in-notes/rfc2965.txt. A central premise of the standard is that informed consent should guide the 
design of systems using cookies. 
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Despite the IETF's standard, Netscape's and Microsoft's browsers have allowed third 
party cookies. They never fully followed the standard. The latest version of web browsers siill 
accept third party cookies by default to satisfy the advertising management companies. 
However, they have improved their cookie management tools. This allows people to mange 
what sites can and can't place cookies. 

C. Platform for Internet Content Selection 

The history of the Platform for Internet Content Selection (PICS) begins with proposed 
legislation to regulate indecent speech on the Internet by Senator Exon in the summer of 199<l. 30 
Senator Exon reintroduced his legislation in February 1 995. This would eventually become tlie 
Communications Decency Act (CDA). 31 On June 14, 1995, the Senate approved an amendment 
(the CDA) to the United States Telecommunications Competition and Deregulation Act of 1995 
that would make it unlawful to transmit indecent material over (he Internet to minors. This 
proposed legislation was followed by the now infamous Time cover story on cyberporn 32 Thin 
combination of media and political pressure threw the upstart Internet companies into action. 

In June of 1995, the W3C began setting up a meeting to discuss technical solutions for 
the regulation of Internet content In August 1 995, the W3C held a members meeting with tw o 
goals in mind. The first was to create a viewpoint independent content labeling system. This 
would allow content to be labeled in many different ways. This labeling system went beyond 
movie ratings of content but was more general to encompass other classification schemes such as 



30 140 CONG. REC. S. 9745 (1994) (including die amendment to S. 1882 by Senator Exon) available at 
http://www.eff. org/Cmsonhip/Intemet_cciiSQRhip_bills/exoi^s 1 822,amend. 

31 Communications Decency Act of 1 995, S.314, 104th Cong. (1995). 

32 Philip Ehner-Dewitt, On a Screen Near You: Cyberporn, TIME, My 3, 1995, available at 
http://ww.time.com/timfyfra 
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